Become a Partner
Become a Partner

Data Protection Addendum

This Data Protection Addendum (“Addendum”) forms part of the Terms of Service between Miracle Advance Technologies Co., Ltd. (“Miracle Advance”) and the Customer. It governs the Customer’s access to and use of Miracle Advance’s services (“Services”). This addendum reflects Miracle Advance’s commitment to data protection and privacy, which aligns with our privacy policy.

Definitions

  • Affiliate: Any entity that controls, is controlled by, or is under common control with either Customer or Miracle Advance, where “control” refers to the power to direct management and policies, whether through ownership, contract or otherwise.
  • Customer Personal Data: Personal Data provided by or made available by the Customer to Miracle Advance, or collected by Miracle Advance on behalf of the Customer, which is processed to perform the Services.
  • Data Protection Laws: Any local, state, or national laws regarding the processing of Personal Data applicable to Miracle Advance in the jurisdictions where Services are provided, including privacy, security, and data protection laws.
  • Security Incident: Any breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data processed by Miracle Advance.
  • Services: According to the Agreement, Miracle Advance supplies the services to the Customer or the Customer’s Affiliates.
  • Third Country: Countries that have yet to receive an adequacy decision from an applicable authority relating to cross-border data transfers of Personal Data, including regulators such as the European Commission.

The terms “Controller,” “Data Subject,” “Personal Data,” “Personal Data Breach,” “Process,” “Processor,” and “Supervisory Authority” have the meanings ascribed to them in applicable Data Protection Laws.

Scope of Addendum

This Addendum applies to Miracle Advance’s processing of Customer Personal Data under the Agreement to the extent such processing is subject to Data Protection Laws.

Types of Personal Data:

  • Identity Data (name, title, position)
  • Contact Data (email, phone, address)
  • Technical Data (IP address, login data, device information)
  • Usage Data (service usage patterns, preferences)

Categories of Data Subjects:

  • Customer’s employees
  • Customer’s end users
  • Customer’s clients

Roles of the Parties

The Parties acknowledge that:

  • The customer acts as a Controller.
  • Miracle Advance acts as a Processor.
  • Both parties shall comply with their respective obligations under Data Protection Laws.

Data Protection Officer

Appointment

Miracle Advance has appointed a Data Protection Officer (“DPO”) to oversee compliance with Data Protection Laws and this Addendum.

The Customer must determine whether it must appoint a DPO under applicable Data Protection Laws.

DPO Contact Details

Name/Title: S M Al Shahaneaz Shaikat – Data Protection Officer (DPO)

Email: shahaneaz@miracleadvance.com

Responsibilities

The DPO oversees Miracle Advance’s data protection strategy and ensures compliance with Data Protection Laws and this Addendum.

The DPO shall serve as a point of contact for supervisory authorities and Data Subjects regarding the processing of Customer Personal Data.

Data Processing Terms

Customer Obligations:

  • Ensure a lawful basis for processing
  • Provide documented instructions
  • Comply with Data Protection Laws
  • Maintain accurate records

Miracle Advance Obligations: Miracle Advance shall:

  • Process Customer Personal Data solely on documented instructions from the Customer, to provide the Services and as necessary to perform its obligations under the Agreement.
  • Implement and maintain appropriate technical and organizational measures to ensure security appropriate to the risk of processing Customer Personal Data.
  • Ensure that personnel authorized to process Customer Personal Data are committed to confidentiality.
  • Notify the Customer without undue delay upon becoming aware of a Personal Data Breach involving the Customer’s Personal Data.
  • Where possible, assist the customer in responding to data subject requests and ensure compliance with obligations under applicable data protection laws.
  • Upon termination or expiry of the Agreement, the Customer may choose to delete or return all Customer Personal Data unless retention is required by applicable law.

Sub-processors

The Customer agrees that Miracle Advance is authorized to engage Sub-processors to process Customer Personal Data, provided that:

  • Miracle Advance notifies the Customer of any intended changes concerning the addition or replacement of Sub-processors.
  • Miracle Advance imposes data protection obligations on sub-processors like those set out in this addendum.
  • Miracle Advance remains liable for any failure by sub-processors to fulfill their obligations to process customer personal data.

Data Subject Rights

Response Procedures:

  • Forward requests to Customer within two business days
  • Assist Customer in responding within 30 days
  • Maintain records of all requests
  • Implement technical measures to facilitate responses

Cost Allocation:

  • Routine assistance at Miracle Advance’s cost
  • Extensive assistance at the Customer’s cost
  • Cost estimates provided in advance

Security Measures

Technical Measures:

  • Encryption at rest and in transit
  • Access control and authentication
  • Firewalls and intrusion detection
  • Regular security updates
  • Backup and recovery procedures

Organizational Measures:

  • Regular staff training
  • Access on a need-to-know basis
  • Security policies and procedures
  • Regular security assessments
  • Incident response plan

International Data Transfers

Transfer Mechanisms:

  • Standard Contractual Clauses
  • Binding Corporate Rules
  • Adequacy decisions
  • Additional safeguards as required

Transfer Impact Assessments:

  • Regular assessments of recipient countries
  • Documentation of safeguards
  • Updates as required by law

Audit Rights

Customer Rights:

  • Annual audit with 30 days notice
  • Additional audits for cause
  • Access to relevant documentation
  • Third-party audit reports

Audit Process:

  • Scope agreement
  • Confidentiality requirements
  • Cost allocation
  • Report sharing

Data Breach Response

Notification Timeline:

  • Initial notification within 24 hours of discovery
  • Detailed report within 72 hours
  • Regular updates as new information becomes available

Notification Contents:

  • Nature of the breach
  • Categories of data affected
  • Approximate number of data subjects affected
  • Likely consequences
  • Measures taken or proposed
  • Contact point for information

Term and Termination

Duration:

  • Coterminous with the main Agreement
  • Survival of specific obligations

Termination Actions:

  • Return or deletion of data
  • Certification of deletion
  • Retention, if legally required

Liability and Indemnification

Liability:

  • Cap at [amount] per incident
  • Unlimited for willful misconduct
  • Exclusions from limitation

Insurance:

  • Required coverage types
  • Minimum coverage amounts
  • Evidence of Coverage

Governing Law

This Addendum is governed by the Agreement’s governing law unless otherwise required by Data Protection Laws.

Miscellaneous

If any provision of this Addendum is held invalid or unenforceable, the remaining provisions shall remain in full force and effect.

For any inquiries regarding this Addendum, please contact us at:

Miracle Advance Technologies Co., Ltd.
2521/34 Ladprao Road, Khlongchaokhunsing, Wangthonglang, Bangkok 10310, Thailand
Email: info@miracleadvance.com
Phone: +66 2514-0314-7

Annex 1 to Data Protection Addendum

Description of Processing Activities for Customer Personal Data

This Annex outlines the details of the processing of Customer Personal Data by Miracle Advance Technologies Co. Ltd. in connection with the Services.

List of Parties

Data Exporter
NameCustomer (as defined in the Agreement)
AddressAs specified in the relevant Order Form.
Contact person’s name, position, and contact detailsAs specified in the relevant Order Form.
Activities relevant to the data transferred under these ClausesAs specified in the relevant Order Form.
Contact person’s name, position, and contact detailsRecipient of Services Miracle Advance Technologies Co. Ltd. provided following the Agreement.
Signature and dateThe signature and date are outlined in the Agreement.
Role (controller/processor)Controller

Data Importer 

NameMiracle Advance Technologies Co. Ltd.
Address2521/34 Ladprao Road, Khlongchaokhunsing, Wangthonglang, Bangkok 10310, Thailand
Contact person’s name, position, and contact detailsMostafa Chowdhury, Co-founder, msac@miracleadvance.com
Activities relevant to the data transferred under these ClausesThe provision of Services to the Customer is under the Agreement.
Signature and dateThe signature and date are outlined in the Agreement.
Role (controller/processor)Processor

Competent Supervisory Authority

  • Supervisory Authority: As determined in accordance with Clause 13 of the EU SCCs.

Processing Information

  • Categories of data subjects: Customer’s authorized users of the Services.
  • Categories of personal data transferred:
    Automatically processed by the Services (provided by customers or authorized users in connection with audit services provided by Miracle Advance Technologies):
    • Names
    • Email IDs
    • Address
    • Date of Birth
    • Employment details
  • Sensitive personal data transferred: None
  • Frequency of transfer: Continuous
  • Nature of processing:
    The processing includes providing the Services described in the Agreement and order forms. This includes querying, cleansing, standardizing, enriching, and securely storing Customer Personal Data.
  • Purpose of data transfer and processing:
    Facilitate performance of the Services in accordance with the Agreement.
  • Business Purposes for Processing (For California consumers under CCPA):
    • Helping ensure security and integrity.
    • Debugging to identify and repair functionality errors.
    • Performing services on behalf of the business (e.g., account maintenance, analytics, storage).
    • Internal research for technological development and demonstration.
    • Verification/maintenance of service or device quality and safety.
    • Retaining subcontractors meeting CCPA service provider standards.
    • Service quality improvement provided no cross-purpose data use.
    • Prevention, detection, and investigation of data security incidents.
  • Retention Period: As outlined in the Agreement, Addendum, and related order forms.
  • Subprocessor Transfers: Details on subject matter, nature, and duration of processing are provided in the Agreement.

Technical and Organizational Security Measures

1. Security Management

  • Designated Security Personnel: Oversight of an Information Security Program.
  • Policies and Assessments: Annual reviews, third-party risk assessments, penetration testing, and patch management.

2. Personnel Security

  • Background checks, confidentiality agreements, and privacy/security training for all personnel accessing Customer Personal Data.

3. Access Controls

  • Formal access management with periodic reviews.
  • Multi-factor authentication (MFA) and single sign-on (SSO) are required for system access.

4. Data Center and Network Security

  • Regular vulnerability scans, disaster recovery testing, and security monitoring.
  • HTTPS encryption for data in transit and encryption for data at rest.

5. Incident Management

  • Defined escalation and incident response procedures for security breaches.

Annex 2: Sub-processors

Name of Sub-ProcessorDescription of ProcessingLocation
Google WorkspaceEmail servicesUSA
SmartTaskWork managementUSA
GitHubCode version controlUSA
LineMessagingJapan
UIHInfrastructure HostingThailand